ZeroHour

CVE-2026-86830

niche

Incorrect Privilege Assignment in AWS TEAM for IAM Identity Center (pre-1.5.1)

CVSS 4.0
8.6 high
EPSS
Published
()
Modified
AI analysis

AWS Temporary Elevated Access Management (TEAM), an AWS Solutions deployment for IAM Identity Center that brokers temporary elevated access, contains an incorrect privilege assignment (CWE-266) in all versions before 1.5.1. Any authenticated remote user who already has application-level access to a TEAM instance can read, approve, modify, or revoke arbitrary access requests, effectively self-approving elevated access and gaining unintended temporary administrative permissions in the AWS accounts managed by that deployment. The flaw requires valid credentials to the application (high privileges per the CVSS 4.0 vector) but no user interaction, and yields high impact on confidentiality, integrity, and availability of the affected accounts. Organizations running TEAM versions prior to 1.5.1, including forks or derivative implementations, are affected. No public proof of concept is known and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog as of this analysis.

What to do: Upgrade TEAM to version 1.5.1 or later as soon as possible, and apply the same fixes to any forked or customized copies of the solution since they will not receive automatic updates. Review TEAM and CloudTrail audit logs for access requests that were approved, modified, or revoked by users who should not have approver rights, and validate that all temporary elevated grants during the vulnerable period were legitimate. As a compensating control, restrict application-level access to TEAM and tighten approval-group membership until the upgrade is complete.

Affected
Amazon Web Services (AWS) Temporary Elevated Access Management (TEAM) for AWS IAM Identity Centerbefore 1.5.1 (fixed in 1.5.1 and later)
Estimated exposure
nichelikely hundreds to low thousands of deployments (order of magnitude), precise count unknown — TEAM is an optional, self-hosted AWS Solutions reference deployment installed individually inside customers' own AWS environments, with no public install counts or internet-exposure scans available, so exposure is limited to the subset of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, approve, modify, or revoke arbitrary access requests, thereby obtaining unintended temporary elevated access to the AWS accounts accessed using the TEAM deployment. This issue has been addressed in TEAM version 1.5.1 or later. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.

Weakness
CWE-266
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.